# New App Store Connect warnings for XOJO builds

**URL:** <https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646>\
**Category:** iOS\
**Created:** [March 19, 2024, 7:32pm UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646 "2024-03-19T19:32:14Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_Balestrieri](https://forum.xojo.com/user_avatar/forum.xojo.com/john_balestrieri/32/9956_2.png) [@John\_Balestrieri](https://forum.xojo.com/u/John_Balestrieri)\
**Post date:** [March 19, 2024, 7:32pm UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/1 "2024-03-19T19:32:15Z")

</div>

I’ve started getting a multiple warnings from App Store Connect about API usage when I upload my builds:

` **ITMS-91053: Missing API declaration** - Your app’s code in the “Photo Tape” file references one or more APIs that require reasons, including the following API categories: [API BEING ACCESSED]. While no action is required at this time, starting May 1, 2024, when you upload a new app or app update, you must include a NSPrivacyAccessedAPITypes array in your app’s privacy manifest to provide approved reasons for these APIs used by your app’s code. For more details about this policy, including a list of required reason APIs and approved reasons for usage, visit: https://developer.apple.com/documentation/bundleresources/privacy_manifest_files/describing_use_of_required_reason_api.`

The API warnings are specifically for:

NSPrivacyAccessedAPICategoryDiskSpace  
NSPrivacyAccessedAPICategoryFileTimestamp  
NSPrivacyAccessedAPICategoryUserDefaults  
NSPrivacyAccessedAPICategorySystemBootTime

They’re definitely not being called by my own declares. Possible causes could be:

- XOJO’s runtime
- MBS plugins
- iOSKit framework
- IOSDesignExtensions framework

Since this may be an issue for others, perhaps we can figure out the root cause? Or figure out a blanket reason to provide in a privacy manifest.

I’ve been working on an app for two years that’s close to release. If the warnings can’t be made to go away, or we don’t have a sufficient explaination in the privacy manifest, then myself and others may be up a creek.

Apple docs on the API calls that issue warnings:

> **[Describing use of required reason API | Apple Developer Documentation](https://developer.apple.com/documentation/bundleresources/privacy_manifest_files/describing_use_of_required_reason_api?language=objc)**
>
> Ensure your use of covered API is consistent with policy.

A possible manifest could look like:

 ![Screenshot 2024-03-19 at 3.55.16 PM](https://forum.xojo.com/uploads/default/original/3X/c/d/cd4b007c80d333bc85b3098e6e2e9e303d940e4f.jpeg)

---

<div class="post-metadata">

**Author:** ![Christian\_Schmitz](https://forum.xojo.com/user_avatar/forum.xojo.com/christian_schmitz/32/158_2.png) [@Christian\_Schmitz](https://forum.xojo.com/u/Christian_Schmitz)\
**Post date:** [March 19, 2024, 7:56pm UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/2 "2024-03-19T19:56:10Z")

</div>

Yes, there is a possibility to track users via things like their free disk space or by reading their user defaults.

These APIs may be in use by Xojo framework, so Xojo may add these automatically for all applications.

---

<div class="post-metadata">

**Author:** ![John\_Balestrieri](https://forum.xojo.com/user_avatar/forum.xojo.com/john_balestrieri/32/9956_2.png) [@John\_Balestrieri](https://forum.xojo.com/u/John_Balestrieri)\
**Post date:** [March 19, 2024, 8:15pm UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/3 "2024-03-19T20:15:40Z")

</div>

I created a PrivacyInfo.xcprivacy resource in Xcode and added it to my XOJO build in a CopyFiles build step, to copy it to the Resources folder.

The binary was uploaded to App Store Connect and I got a successful upload email, rather than the warning email I usually get. For the 4 APIs indicated, these are the reasons I gave:

**System Boot Time**

> 35F9.1
> 
> Declare this reason to access the system boot time in order to measure the amount of time that has elapsed between events that occurred within the app or to perform calculations to enable timers.
> 
> Information accessed for this reason, or any derived information, may not be sent off-device. There is an exception for information about the amount of time that has elapsed between events that occurred within the app, which may be sent off-device.

**User Defaults**

> CA92.1
> 
> Declare this reason to access user defaults to read and write information that is only accessible to the app itself.
> 
> This reason does not permit reading information that was written by other apps or the system, or writing information that can be accessed by other apps.

**File Timestamp**

> C617.1
> 
> Declare this reason to access the timestamps, size, or other metadata of files inside the app container, app group container, or the app’s CloudKit container.

**Disk Space**

> E174.1
> 
> Declare this reason to check whether there is sufficient disk space to write files, or to check whether the disk space is low so that the app can delete files when the disk space is low. The app must behave differently based on disk space in a way that is observable to users.
> 
> Information accessed for this reason, or any derived information, may not be sent off-device. There is an exception that allows the app to avoid downloading files from a server when disk space is insufficient.

These are based on _conservative, educated guesses_ but it would be great if XOJO could clarify, or better yet, provide a default manifest (either now or in future builds)

---

<div class="post-metadata">

**Author:** ![John\_Balestrieri](https://forum.xojo.com/user_avatar/forum.xojo.com/john_balestrieri/32/9956_2.png) [@John\_Balestrieri](https://forum.xojo.com/u/John_Balestrieri)\
**Post date:** [March 19, 2024, 8:23pm UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/4 "2024-03-19T20:23:39Z")

</div>

Yes, there are privacy considerations with these APIs. The main concern is the uninterrupted distribution of non-privacy-violating XOJO apps in the App Store. 🙃

---

<div class="post-metadata">

**Author:** ![Björn\_Eiríksson](https://forum.xojo.com/letter_avatar_proxy/v4/letter/b/da6949/32.png) [@Björn\_Eiríksson](https://forum.xojo.com/u/Bj%C3%B6rn_Eir%C3%ADksson)\
**Post date:** [March 19, 2024, 9:07pm UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/5 "2024-03-19T21:07:17Z")

</div>

This becomes difficult in cases like this when Xojo has huge framework of everything and almost nothing conditionally compiled out then you have things like File dates and File size that always would get compiled in I am guessing.

As to explain to Apple why you have it I am not sure how you can ☹

---

<div class="post-metadata">

**Author:** ![Greg\_O](https://forum.xojo.com/user_avatar/forum.xojo.com/greg_o/32/22785_2.png) [@Greg\_O](https://forum.xojo.com/u/Greg_O)\
**Post date:** [March 19, 2024, 11:03pm UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/6 "2024-03-19T23:03:47Z")

</div>

Take that file you created and drag it directly into the navigator. The IDE will merge those items into the app’s plist file.

---

<div class="post-metadata">

**Author:** ![Greg\_O](https://forum.xojo.com/user_avatar/forum.xojo.com/greg_o/32/22785_2.png) [@Greg\_O](https://forum.xojo.com/u/Greg_O)\
**Post date:** [March 19, 2024, 11:05pm UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/7 "2024-03-19T23:05:03Z")

</div>

What we did when I was there was add generic strings by default and then letting the user change the strings if they actually used the feature.

---

<div class="post-metadata">

**Author:** ![John\_Balestrieri](https://forum.xojo.com/user_avatar/forum.xojo.com/john_balestrieri/32/9956_2.png) [@John\_Balestrieri](https://forum.xojo.com/u/John_Balestrieri)\
**Post date:** [March 19, 2024, 11:11pm UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/8 "2024-03-19T23:11:31Z")

</div>

Thanks; I’ll try dragging it into the project navigator. As it turns out, I just got an email saying that there are still issues, so copying it to the bundle resources didn’t quite work.

(The file itself isn’t a .plist file, it’s a .xcprivacy file, and XOJO doesn’t merge it with the info.plist.)

---

<div class="post-metadata">

**Author:** ![John\_Balestrieri](https://forum.xojo.com/user_avatar/forum.xojo.com/john_balestrieri/32/9956_2.png) [@John\_Balestrieri](https://forum.xojo.com/u/John_Balestrieri)\
**Post date:** [March 20, 2024, 12:14am UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/9 "2024-03-20T00:14:10Z")

</div>

Trying another test: Dragging “PrivacyInfo.xcprivacy" into the project navigator, and XOJO puts the file where it needs to be when you building the app: At the root of the app bundle.

 ![Screenshot 2024-03-19 at 8.24.21 PM](https://forum.xojo.com/uploads/default/original/3X/4/5/45d6e1fd33dd1b309bf9baeebb30498422d73cd9.png)

I created a test app in Xcode and built it. Xcode copies PrivacyInfo.xcprivacy to the same location.

Uploading to App Store Connect again and fingers-crossed. 🤞

John

---

<div class="post-metadata">

**Author:** ![John\_Balestrieri](https://forum.xojo.com/user_avatar/forum.xojo.com/john_balestrieri/32/9956_2.png) [@John\_Balestrieri](https://forum.xojo.com/u/John_Balestrieri)\
**Post date:** [March 20, 2024, 12:22am UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/10 "2024-03-20T00:22:48Z")

</div>

This isn’t a wholy-unheard of problem. iOS apps built with Unity will encounter the same issue:

> **[Unity - Manual: Apple’s privacy manifest policy requirements](https://docs.unity3d.com/Manual/apple-privacy-manifest-policy.html)**

And if you use C# in Unity, the inclusion of the whole C# framework is a similar issue:

> 1. Assess if your native application code uses any of the following APIs:
> 
> - APIs listed under the [Required Reasons API](https://developer.apple.com/documentation/bundleresources/privacy_manifest_files/describing_use_of_required_reason_api?language=objc) category.
> - The [C# .Net framework APIs](https://docs.unity3d.com/Manual/apple-privacy-manifest-policy.html#CSharpDotNetAPIs) in Unity framework.

However, what’s different here is that I haven’t seen a word from XOJO about this and the deadline is approaching quickly. Unity has docs, at least. If there isn’t one already, I’d suggest a blog post, at the very least. 🤷‍♂️

John

---

<div class="post-metadata">

**Author:** ![John\_Balestrieri](https://forum.xojo.com/user_avatar/forum.xojo.com/john_balestrieri/32/9956_2.png) [@John\_Balestrieri](https://forum.xojo.com/u/John_Balestrieri)\
**Post date:** [March 20, 2024, 3:00am UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/11 "2024-03-20T03:00:08Z")

</div>

🔝This worked. No warning more emails from Apple.

---

<div class="post-metadata">

**Author:** ![Greg\_O](https://forum.xojo.com/user_avatar/forum.xojo.com/greg_o/32/22785_2.png) [@Greg\_O](https://forum.xojo.com/u/Greg_O)\
**Post date:** [March 20, 2024, 6:16am UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/12 "2024-03-20T06:16:25Z")

</div>

You should change the extension of that file to `plist` and reimport it.

---

<div class="post-metadata">

**Author:** ![John\_Balestrieri](https://forum.xojo.com/user_avatar/forum.xojo.com/john_balestrieri/32/9956_2.png) [@John\_Balestrieri](https://forum.xojo.com/u/John_Balestrieri)\
**Post date:** [March 20, 2024, 11:09am UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/14 "2024-03-20T11:09:58Z")

</div>

It actually needs to be a separate file called “PrivacyInfo.xcprivacy” and is a new file-based resource type you can create in Xcode.

> Apps and third-party SDKs — distributed as XCFrameworks, Swift packages, or Xcode projects — can contain a privacy manifest file, named `PrivacyInfo.xcprivacy` .

> **[Privacy manifest files | Apple Developer Documentation](https://developer.apple.com/documentation/bundleresources/privacy_manifest_files)**
>
> Describe the data your app or third-party SDK collects and the reasons required APIs it uses.

---

<div class="post-metadata">

**Author:** ![Jeremie\_L](https://forum.xojo.com/user_avatar/forum.xojo.com/jeremie_l/32/150_2.png) [@Jeremie\_L](https://forum.xojo.com/u/Jeremie_L)\
**Post date:** [March 20, 2024, 11:36am UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/15 "2024-03-20T11:36:19Z")

</div>

> [@John\_Balestrieri](#):
>
> PrivacyInfo.xcprivacy

Would you mind sharing that file?  
I will include it with iOSDesignExtensions so everyone has easy access to it 🙂

---

<div class="post-metadata">

**Author:** ![Björn\_Eiríksson](https://forum.xojo.com/letter_avatar_proxy/v4/letter/b/da6949/32.png) [@Björn\_Eiríksson](https://forum.xojo.com/u/Bj%C3%B6rn_Eir%C3%ADksson)\
**Post date:** [March 20, 2024, 11:37am UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/16 "2024-03-20T11:37:20Z")

</div>

I imagine Xojo may need to add something to the plugin SDK also and or package iOS plugins into something else than dylib, like framework of some sort maybe. Since I am not sude a PrivacyInfo file can be embedded on dylib.

---

<div class="post-metadata">

**Author:** ![John\_Balestrieri](https://forum.xojo.com/user_avatar/forum.xojo.com/john_balestrieri/32/9956_2.png) [@John\_Balestrieri](https://forum.xojo.com/u/John_Balestrieri)\
**Post date:** [March 20, 2024, 11:39am UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/17 "2024-03-20T11:39:47Z")

</div>

I could share a quick tutorial step-by-step later today, but these are each developer’s privacy declarations to Apple and shouldn’t be copy-and-pasted from one developer to another.

Basically, go to Xcode and make a new privacy manifest file. It’s an option in the New dialog. Then select the entries that correspond to the descriptions I linked above.

---

<div class="post-metadata">

**Author:** ![Javier\_Menendez](https://forum.xojo.com/user_avatar/forum.xojo.com/javier_menendez/32/15692_2.png) [@Javier\_Menendez](https://forum.xojo.com/u/Javier_Menendez)\
**Post date:** [March 20, 2024, 2:06pm UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/18 "2024-03-20T14:06:08Z")

</div>

Thank you for pointing this out @John_Balestrieri !

For sure we will publish a blog post about it… and find a way to get all this integrated in a further release of Xojo.

---

<div class="post-metadata">

**Author:** ![Javier\_Menendez](https://forum.xojo.com/user_avatar/forum.xojo.com/javier_menendez/32/15692_2.png) [@Javier\_Menendez](https://forum.xojo.com/u/Javier_Menendez)\
**Post date:** [March 20, 2024, 3:28pm UTC](https://forum.xojo.com/t/new-app-store-connect-warnings-for-xojo-builds/79646/19 "2024-03-20T15:28:18Z")

</div>

> [@John\_Balestrieri](#):
>
> PrivacyInfo.xcprivacy

…and added to Issues, so we can track this a Feature Request for the IDE / iOS: [https://tracker.xojo.com/xojoinc/xojo/-/issues/75903](https://tracker.xojo.com/xojoinc/xojo/-/issues/75903)
